Nova Patents
US8867747B2

Key generation for networks

Summary by NHIP

Network Key Generation

The method configures a key server with a pseudo-random function to generate cryptographic data structures and epoch values for a set of gateways. The system selectively distributes unique user secret data to each gateway while revoking specific members and distributing new epoch values to remaining groups for encrypted communication.

Claim Score by NHIP

Read claim 15, the broadest

Abstract

Systems, methods, and other embodiments associated with key generation for networks are described. One example method includes configuring a key server with a pseudo-random function (PRF). The key server may provide keying material to gateways. The method may also include controlling the key server to generate a cryptography data structure (e.g., D-matrix) based, at least in part, on the PRF and a seed value. The method may also include controlling the key server to selectively distribute a portion of the cryptography data structure and/or data derived from the cryptography data structure to a gateway. The gateway may then encrypt communications based, at least in part, on the portion of the cryptography data structure. The method may also include selectively distributing an epoch value to members of the set of gateways that may then decrypt an encrypted communication based, at least in part, on the epoch value.

US8867747B2, drawing sheet 1
Sheet 1 of 8

Term

6.5 yearsleft in the term

Expires 9 March 2033, including 1,439 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

22 claims: 4 independent, 18 dependent

  1. 1
    A method comprising:configuring a key server (KS) with a pseudo-random function (PRF), the KS being associated with a set of gateways for which the KS provides keying material;controlling the KS to generate a cryptographic data structure for a symmetrical key generation system (KGS) based, at least in part, on the PRY and a seed value;controlling the KS to generate an epoch value;controlling the KS to selectively distribute the epoch value and KGS user secret data derived from the cryptographic data structure to a member of the set of gateways;wherein the KGS user secret data and the epoch value are for generating keys for encrypted communications;wherein a different set of KGS user secret data is provided to different members of the set of gateways;revoking at least one member of the set of gateways;generating a new epoch value;and distributing the new epoch value to a selected group of the set of gateways that does not include the revoked member, where the selected group of the set of gateways communicate using encryption among the selected group, and where encryption is based on keys generated, at least in part, on the KGS user secret data and the new epoch value.
  2. 9
    An apparatus, comprising:a security logic stored in a non-transient memory and executable by an associated processor to create a cryptography data structure based, at least in part, on a pseudo-random function (PRF) and a random seed value and to create a KGS user secret data based on the cryptography data structure the security logic generating an epoch value;and a transmit logic stored in a non-transient memory and executable by an associated processor to selectively transmit the KGS user secret data and the epoch value to a member of a set of group members (GMs) in a network, where the member of the set of GMs selectively encrypts and decrypts messages based, at least in part, on the KGS user secret data and the epoch value;wherein the GMs encrypt communications based on keys generated, at least in part, on the KGS user secret data and the epoch value;wherein a different set of KGS user data is provided to each member of the set of GMs;the security logic revoking at least one member of the set of group members;the security logic generating a new epoch value;and the transmit logic distributing the new epoch value to a selected group of the set of group members that does not include the revoked member, where the selected group of the set of group members communicate using encryption among the selected group, and where encryption is based on keys generated, at least in part, on the KGS user secret data and the new epoch value.
  3. 14
    A system, comprising:circuitry for configuring a key server (KS) with a pseudo-random function (PRF), the KS being associated with a set of gateways in a network for which the KS provides keying material;circuitry for controlling the KS to generate a cryptography data structure (CDS) for a symmetrical key generation system (KGS) based, at least in part, on the PRF and a seed value;circuitry for the controlling the KS to generate an epoch value;circuitry for selectively transmitting KGS user secret data based on a portion of the CDS to a member of the set of gateways and the epoch value, where the member of the set of gateways is to selectively encrypt and decrypt messages based, at least in part, on the KGS user secret data and the epoch value;circuitry for controlling the KS to delete the CDS;and circuitry for controlling the KS to regenerate at least a portion of the CDS using the PRF and the seed value;wherein a different set of KGS user secret data is provided to different members of the set of gateways.
  4. 15
    Broadest claimClaim Score 43, average(NHIP)Logic encoded in one or more non-transitory computer readable medium for execution and when executed operable to perform a method, the method comprising:configuring a key server (KS) with a pseudo-random function (PRF), the KS being associated with a set of gateways for which the KS provides keying material;controlling the KS to generate a cryptographic data structure for a symmetrical key generation system (KGS) based, at least in part, on the PRF and a seed value;controlling the KS to generate an epoch value;controlling the KS to selectively distribute the epoch value and KGS user secret data derived from the cryptographic data structure to a member of the set of gateways;wherein the KGS user secret data and the epoch value are for generating keys for encrypted communications;wherein a different set of KGS user secret data is provided to different members of the set of gateways;controlling the KS to delete the cryptographic data structure;and regenerating at least a portion of the cryptographic data structure using the PRF and the seed value.